Crypto Fraud Watch: $320 Million Leaves Liquid's Federation Wallet, a Coldcard Thief Reaches for THORChain, and Berlin Refuses 30 Bitcoin
The largest single crypto loss of 2026 landed this weekend, and it came out of a Bitcoin sidechain rather than an exchange. Alongside it: stolen Coldcard bitcoin moving through a mixer, a German state refusing a ransom, and a new Indian unit built to trace crypto through drug networks.
A $320 Million Peg-Out Empties 95% of Liquid's Reserve
About 3,996 BTC left the Liquid Network federation wallet on September 6, roughly $320 million. SideSwap says a customer sent 4,000 L-BTC to its peg-out service at 14:05 UTC and the federation paid out on Bitcoin 23 minutes later, under a valid authorization. No federation or peg-out authorization key was compromised. On-chain analysts point to a range-proof cache flaw in Elements, patched upstream but absent from the build the network was running. The sidechain is paused with roughly 197 BTC left, down from about 4,200.
An on-chain message claimed white-hat status and promised most coins back once nodes are patched. That label does less legal work than people assume. Authorization is the central question under the Computer Fraud and Abuse Act, and following a signature path to extract value the protocol never meant to release is not permission to take it. A negotiated return would shrink the loss without curing the taking.
The Coldcard Thief Reaches for THORChain
Galaxy Research reported at 02:19 UTC on September 7 that the Wave 3 Coldcard operator had moved 97.09 BTC out of 12 vaults, about 45% of that wave, through THORChain swaps and Bitcoin CoinJoins. Roughly 117 BTC across 282 vaults sits untouched.
If your coins are in that set, the practical clock started this weekend, not in July when the seed-generation bug originated. Tracing is cheap while funds sit still and expensive after a mixer, and a court asked to freeze assets wants a legible trail.
Berlin Refuses 30 Bitcoin, and the Files Go Out Anyway
The Rhysida group claimed 5.7 terabytes from Berlin's state network and auctioned it at a 30 BTC minimum, near two million euros. Berlin declined to pay, the deadline lapsed September 4, and the data was published. On September 6 the city said a second package containing access credentials had been released.
Refusing is the defensible call, and paying would not have retired the harder obligations: identifying affected employees, residents, and businesses, then notifying them on statutory deadlines. Any organization that shared a credential with a Berlin state system should treat it as burned.
India Builds Crypto-Tracing Capacity Without Changing Its Crypto Rules
At a September 6 press conference in Panaji, Goa, Home Minister Amit Shah said the government has constituted a Darknet-Crypto Cell inside its anti-narcotics task force to trace crypto payments, encrypted messaging, and dead-drop deliveries. A day earlier, the Enforcement Directorate arrested two people in a 40 crore rupee Hashpe fraud case.
Note what the briefing did not do. No new virtual digital asset statute, no ban, and no change to the 30% tax under Section 115BBH, the 1% TDS under Section 194S, or FIU-IND registration duties. This is capacity rather than rulemaking, which means more freeze requests and wallet-attribution demands on platforms serving Indian users.
How to Protect Yourself
None of this weekend's losses came from a weak password. If you hold Bitcoin on a hardware wallet, check whether your model and firmware fall inside a disclosed seed-generation defect and migrate to a fresh seed if so. If you use a sidechain, bridge, or peg, treat assets there as exposed to that system's software risk rather than Bitcoin's. Expect the Berlin credential dump to be mined for targeted phishing.
Recovery depends on speed. Report to law enforcement, preserve wallet and device records before they rotate, and get tracing help while funds are still identifiable. Where a protocol's own unpatched code caused the loss, claims may run against the operator as well as the taker.
At Coin Counsel, we work with individuals and businesses navigating the legal fallout of crypto fraud โ whether you're a victim seeking recovery, a company facing regulatory scrutiny, or a project working to stay compliant in an increasingly complex legal landscape. The rules are evolving fast, and the cost of getting it wrong has never been higher. Contact us at coin-counsel.com to speak with a crypto-focused attorney today.
Disclaimer
This blog post is for informational purposes only and does not constitute legal advice. Reading this content does not create an attorney-client relationship between you and Coin Counsel or Franco Law PLLC. The legal landscape surrounding cryptocurrency is rapidly evolving and varies by jurisdiction. Do not act or refrain from acting based on information in this post without first consulting a qualified attorney. If you believe you have been the victim of crypto fraud, contact us at coin-counsel.com for a consultation.